CVE-2026-1978

Severity CVSS v4.0:
MEDIUM
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
06/02/2026
Last modified:
06/02/2026

Description

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing a manipulation results in direct request. It is possible to initiate the attack remotely. The exploit is now public and may be used. You should change the configuration settings.